Home / Insights / Compliance
Compliance

AUSTRAC Tranche 2: what newly-regulated businesses must do now

By Financial Crime Advisory · 30 July 2026 · 13 min read

Australia's anti-money-laundering regime just got a great deal bigger. The Tranche 2 reforms have pulled tens of thousands of professional-services firms — lawyers, accountants, real estate agents and others — into the AML/CTF Act for the first time. Obligations for these newly-captured entities commenced on 1 July 2026, and the AUSTRAC enrolment window for them closed on 29 July 2026. If your firm provides a designated service, you are almost certainly already a reporting entity. This guide explains what changed, whether you're captured, and exactly what you need in place.

On this page

What the Tranche 2 reforms actually are

For most of the last two decades, Australia's Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act) applied mainly to banks, remitters, gaming operators and other financial businesses. A whole class of professions that routinely handle high-value transactions and help move, structure and hold money sat outside it. Internationally these are known as designated non-financial businesses and professions, and the global standard-setter for AML has long expected countries to bring them into the net. In Australia, that expansion is what everyone calls "Tranche 2".

The reforms extend the AML/CTF Act so that when a firm in one of the captured professions provides a specified activity — a designated service — that firm becomes a reporting entity and takes on the same core family of obligations that banks have carried for years. The obligations are scaled to risk, not identical in volume to a major bank's, but the framework is the same: know your customer, understand your money-laundering and terrorism-financing risk, monitor for the unusual, report it, and be able to prove you did all of it.

The short version. Tranche 2 does not create a new, separate rulebook for professionals. It puts newly-captured professions inside the existing AML/CTF regime — the same Act, the same regulator (AUSTRAC), the same building blocks of enrolment, program, risk assessment, due diligence, monitoring and reporting.

Who is captured

The reforms target the professions most often used — knowingly or not — to launder proceeds, hide beneficial ownership, or move value through property and high-value goods. In broad terms, the captured groups are:

Two things trip firms up here. First, being in one of these industries does not automatically capture you — and not being an obvious "law firm" or "accountant" does not automatically exempt you. What matters is whether you provide a designated service. Second, many firms provide a mix of services, only some of which are designated. The task is to look through your service lines, not just your business card.

What a "designated service" means — and why it makes you a reporting entity

The pivot point of the entire regime is the concept of a designated service. The AML/CTF Act contains a list of specific activities. Provide one of those activities to a customer, and the law treats you as a reporting entity for that service, with obligations attached. It is the activity that triggers coverage, not the label on your firm.

This activity-based test is deliberate. A single practice might offer a dozen services, of which only two or three are designated. A firm that thinks of itself as "just doing conveyancing" may be squarely captured. The practical implication is that the first serious piece of work is a service-line mapping exercise: list what you actually do for clients, and test each activity against the designated-services list. That determination drives everything downstream — enrolment, the scope of your program, which customers need due diligence, and what you monitor.

Because coverage is per-service, it is entirely possible to be a reporting entity for one part of your business and outside the regime for another. Getting this scoping right is not a technicality; it defines the size and shape of your compliance obligation. Our AML/CTF advisory team spends a large part of every Tranche 2 engagement precisely here, because a wrong call at this stage propagates into every later control.

The timeline that matters — and why "already obligated" is the key phrase

There are two firm dates every captured business needs to hold in mind:

That is the uncomfortable reality this article exists to name plainly: for a large number of firms, the questions are no longer "when will this affect me?" but "am I already exposed, and how fast can I fix it?" If you are reading this and you provide a designated service, treat yourself as obligated today and work backwards to close the gap. We deal with the remediation path in detail below.

Don't wait for a letter. The obligation exists because of what you do, not because AUSTRAC has contacted you. Firms that self-identify, enrol and remediate promptly are in a far stronger position than firms that wait to be found. Silence from the regulator is not a safe harbour.

The eight things a captured business must have in place

Whatever your profession, the AML/CTF framework asks for the same core set of controls. Here are the eight that a Tranche 2 reporting entity needs to stand up.

1. AUSTRAC enrolment and registration

Every reporting entity must be enrolled with AUSTRAC. Enrolment is the formal step that puts you on the register and connects you to AUSTRAC's reporting channels. With the enrolment window having closed on 29 July 2026, firms that have not yet enrolled should treat this as the single most urgent item — you cannot lodge the reports the Act requires from a business that is not enrolled.

2. An AML/CTF program (Part A and Part B)

Your AML/CTF program is the written backbone of your compliance. It has two halves. Part A sets out your risk-based systems and controls: how you identify, assess, manage and reduce your money-laundering and terrorism-financing risk, plus governance, oversight, the role of your compliance officer, training and independent review. Part B covers customer identification — the procedures you follow to know who your customer is before you provide a designated service. The program must be documented, approved at the right level, and genuinely used, not filed and forgotten.

3. An ML/TF risk assessment

Underneath the program sits a documented money-laundering and terrorism-financing risk assessment. This is where you think through the risk your particular business faces across your customers, the services you provide, the delivery channels you use, and the countries or jurisdictions you touch. The risk assessment is not paperwork for its own sake — it is what makes your program "risk-based". Your controls, your due-diligence intensity and your monitoring should all trace back to what this assessment concludes.

4. KYC, customer due diligence and enhanced due diligence

Before providing a designated service, you must know who you are dealing with. Customer due diligence (CDD) means identifying and verifying your customer — and, where relevant, the beneficial owners behind them and the purpose of the relationship. Where the risk is higher — for example, politically exposed persons, opaque structures, or higher-risk jurisdictions — you must apply enhanced customer due diligence (ECDD), digging deeper and, where appropriate, obtaining senior approval to proceed. Good CDD is also good client practice; it protects the firm as much as it satisfies the regulator.

5. Ongoing transaction monitoring, SMRs and TTRs

Onboarding is not a one-off. You must monitor your customers and their transactions on an ongoing basis, looking for activity that is unusual, inconsistent with what you know about the customer, or otherwise suspicious. Two reporting obligations flow from this:

Both require you to have a process for spotting the trigger, making the decision, and lodging the report within the required timeframe — and to keep the customer relationship confidential where the law requires it.

6. An AML/CTF compliance officer

You must appoint a nominated AML/CTF compliance officer — a person at management level with responsibility for the program's day-to-day operation and its oversight. In a small firm this may be a partner or principal wearing an additional hat; the point is that a named, accountable person owns compliance, rather than it being everyone's job and therefore no one's.

7. Staff training and record-keeping

Your people are your first line of detection. Staff who deal with customers or transactions need training appropriate to their role, so they can recognise red flags and know what to do. Alongside training sits record-keeping: you must retain identification records, transaction records and program documentation for the periods the Act requires, so that you can demonstrate compliance if AUSTRAC asks.

8. An independent review of the program

Finally, your AML/CTF program must be subject to independent review — an assessment, conducted by someone independent of the program's day-to-day operation, of whether it is appropriate to your risk and whether it is actually working. This is not a light-touch requirement; a genuine independent review looks for the gaps between what your program says and what your firm does. It is one of the clearest signals to a regulator that you are taking the regime seriously, and it is one of the services we deliver most often. You can read more on our services page.

Your Tranche 2 compliance checklist

The table below turns those eight obligations into a working checklist. Use it to take stock of where your firm stands right now — every row you cannot honestly tick is an open exposure.

RequirementWhat it meansStatus to reach
ScopingMap your service lines against the designated-services list to confirm whether — and where — you're captured.Documented determination of which services are designated
AUSTRAC enrolmentRegister as a reporting entity so you can lodge reports. Window closed 29 July 2026.Enrolled and on the register
AML/CTF programWritten Part A (systems & controls) and Part B (customer identification), approved and in use.Documented, approved, operational
ML/TF risk assessmentAssess risk across customers, services, channels and jurisdictions; drive your controls from it.Documented and reflected in controls
KYC / CDD & ECDDIdentify and verify customers and beneficial owners; apply enhanced diligence to higher-risk cases.Applied before providing a designated service
Monitoring, SMRs & TTRsOngoing monitoring, with processes to lodge suspicious matter and threshold transaction reports on time.Live monitoring and reporting process
Compliance officerA named, management-level person accountable for the program.Appointed and empowered
Training & recordsRole-appropriate staff training and retention of identification, transaction and program records.Delivered and retained to required periods
Independent reviewAn independent assessment of whether the program is appropriate and effective.Scheduled and conducted independently

What "already exposed" means — and how remediation works

Because obligations commenced on 1 July 2026 and enrolment closed on 29 July 2026, a firm that provides a designated service and has done nothing is not in a grace period — it is in breach of live obligations. That is worth stating without softening, because the instinct in professional-services firms is often to hope the issue is theoretical. It is not; the exposure is real from the moment you provide a designated service.

The good news is that remediation is a well-worn path, and regulators generally distinguish between a firm that identifies its own gap and moves decisively to close it, and one that ignores the problem. A sensible remediation sequence looks like this:

  1. Confirm capture. Map your services and determine, on the record, which are designated and from what date you began providing them.
  2. Enrol without further delay. Get onto the AUSTRAC register so you can meet your reporting obligations.
  3. Stand up an interim program. Put a workable Part A and Part B in place now, even if it will be refined — an operating program beats a perfect draft.
  4. Document your risk assessment. Capture your ML/TF risk so your controls are demonstrably risk-based.
  5. Start due diligence and monitoring. Apply CDD to current designated-service customers and begin monitoring, with a process ready for SMRs and TTRs.
  6. Record everything. Keep a clear, dated trail of your remediation decisions and actions — it is evidence of good faith.
  7. Book the independent review. Schedule an independent look at what you've built so gaps are found by you, not by the regulator.
Remediation is a posture, not a panic. The firms that come through Tranche 2 well are not the ones that were perfectly ready on day one — very few were. They're the ones that acted quickly, documented honestly, and closed the gap in a deliberate order. That is entirely achievable, even from behind.

What to do this month

If you take nothing else from this guide, take these five moves and start them now:

  1. Decide, in writing, whether you're captured. Map your services against the designated-services list. If any service is designated, you are a reporting entity for it.
  2. Enrol with AUSTRAC. The window has closed, which makes this more urgent, not less. You cannot report from an un-enrolled business.
  3. Stand up a working AML/CTF program and risk assessment. Get Part A, Part B and a documented ML/TF risk assessment operating — interim is fine, absent is not.
  4. Name your compliance officer and train your people. Put an accountable person in place and make sure client-facing staff can spot and escalate red flags.
  5. Get an independent set of eyes on it. An independent review will tell you where the real gaps are before anyone else does.

None of this needs to be done alone, and it does not need to grind your practice to a halt. The obligations are scaled to your risk, and a proportionate program built in the right order will hold up. If you're unsure where your firm sits — captured or not, exposed or covered — that uncertainty is itself the thing to resolve first. Talk to a specialist and we'll tell you straight where you stand and what the fastest safe path forward looks like.

Common questions

Tranche 2, answered

What is AUSTRAC Tranche 2?

Tranche 2 is the expansion of Australia's AML/CTF regime to a group of professions and businesses that were previously outside it — often called designated non-financial businesses and professions. It brings lawyers and conveyancers, accountants and bookkeepers, real estate agents and buyers' agents, property developers, dealers in precious metals and stones, and trust and company service providers into the AML/CTF Act when they provide a designated service.

Who is captured by the Tranche 2 reforms?

The captured groups include legal practitioners and conveyancers, accountants, bookkeepers and BAS agents, real estate agents and buyers' agents, property developers, dealers in precious metals and stones, and trust and company service providers. Whether you're captured depends on whether you actually provide a designated service — not simply on your industry label.

When did the Tranche 2 obligations start?

Obligations for Tranche 2 entities commenced on 1 July 2026, and the AUSTRAC enrolment window for these entities closed on 29 July 2026. Many firms are therefore already obligated and, if they haven't enrolled, already exposed.

What is a "designated service"?

A designated service is a specific activity listed in the AML/CTF Act. Providing one to a customer is what makes a business a reporting entity with AML/CTF obligations. It's the activity, not the profession, that triggers the regime — so the test is whether any service your firm delivers appears on the list.

What must a captured business have in place?

At a minimum: AUSTRAC enrolment, an AML/CTF program covering Part A systems and controls and Part B customer identification, a documented ML/TF risk assessment, KYC and customer due diligence including enhanced due diligence for higher-risk customers, ongoing transaction monitoring with suspicious matter reports and threshold transaction reports, a nominated AML/CTF compliance officer, staff training and record-keeping, and an independent review of the program.

We missed the enrolment deadline — what now?

If you provide a designated service and haven't enrolled, you're likely already carrying an obligation you're not meeting. The response is prompt remediation: confirm whether you're captured, enrol without further delay, stand up an interim AML/CTF program, document a risk assessment, and begin monitoring and reporting. Acting quickly and keeping a clear record of your remediation steps is far better than waiting.

FCA
Financial Crime Advisory
Australia's specialist fraud, AML/CTF and loss-prevention consultancy — helping newly-regulated firms scope, build and independently review their AML/CTF programs.

Not sure if Tranche 2 captures you?

Tell us what your firm does for clients and we'll tell you straight — captured or not, exposed or covered — and the fastest safe path to a compliant AML/CTF program.